Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
82.322 exploits
GitHub PoC
Check for CVE-2014-0160
CVE-2014-0160HIGHsob ataque25 abr 2023
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir ↗
GitHub PoC
2022 Spring Prof. 謝續平
CVE-2022-21907CRITICAL25 abr 2023
HTTP Protocol Stack Remote Code Execution Vulnerability
70RISCO
abrir ↗
GitHub PoC
UnrealIRCd 3.2.8.1 backdoor command execution exploit in Python 3 (CVE-2010-2075).
CVE-2010-2075—25 abr 2023
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RISCO
abrir ↗
Exploit-DB
PaperCut NG/MG 22.0.4 - Authentication Bypass
CVE-2023-27350CRITICALsob ataqueransomwarewebappsmultiple25 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2019-9081—25 abr 2023
20RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27524HIGHsob ataque25 abr 2023
Apache Superset: Session validation vulnerability when using provided default SECRET_KEY
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-29464CRITICALsob ataqueransomware25 abr 2023
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /file
100RISCO
abrir ↗
GitHub PoC
andyhsu024/CVE-2021-29447
CVE-2021-29447HIGH24 abr 2023
WordPress Authenticated XXE attack when installation is running PHP 8
63RISCO
abrir ↗
Metasploit600
invscout RPM Privilege Escalation
CVE-2023-28528HIGH24 abr 2023
IBM AIX command execution
36RISCO
abrir ↗
Metasploit600
Ivanti Avalanche FileStoreConfig File Upload
CVE-2023-28128HIGH24 abr 2023
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could
58RISCO
abrir ↗
GitHub PoC
msd0pe-1/CVE-2023-31747
CVE-2023-31747HIGH24 abr 2023
Wondershare Filmora 12 (Build 12.2.1.2088) was discovered to contain an unquoted service path vulnerability via the comp
41RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALsob ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2021-41277CRITICALsob ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir ↗
GitHub PoC★ 13
CVE-2023-22894
CVE-2023-22894CRITICAL24 abr 2023
Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting
48RISCO
abrir ↗
GitHub PoC★ 1
RubXkuB/PoC-Metabase-CVE-2021-41277
CVE-2021-41277CRITICALsob ataque24 abr 2023
GeoJSON URL validation can expose server files and environment variables to unauthorized users
100RISCO
abrir ↗
GitHub PoC★ 15
CVE-2023-1671-POC, based on dnslog platform
CVE-2023-1671CRITICALsob ataque24 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗
GitHub PoC★ 3
Pre-Auth RCE in Sophos Web Appliance
CVE-2023-1671CRITICALsob ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2021-26855CRITICALsob ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
remote-with-credentials
CVE-2022-40799HIGHsob ataque23 abr 2023
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l
83RISCO
abrir ↗
GitHub PoC★ 1
glen-pearson/ProxyLogon-CVE-2021-26855
CVE-2021-26855CRITICALsob ataqueransomware23 abr 2023
Microsoft Exchange Server Remote Code Execution Vulnerability
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-1671CRITICALsob ataque23 abr 2023
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISCO
abrir ↗
GitHub PoC★ 57
Proof of Concept Exploit for PaperCut CVE-2023-27350
CVE-2023-27350CRITICALsob ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
GitHub PoC★ 1
Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.
CVE-2022-1609CRITICAL22 abr 2023
The School Management < 9.9.7 - Unauthenticated RCE via REST api
75RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALsob ataqueransomware22 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
VulnCheck XDB
infoleak
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
VulnCheck XDB
initial-access
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
Metasploit300
Piwigo CVE-2023-26876 Gather Credentials via SQL Injection
CVE-2023-26876HIGH21 abr 2023
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via t
36RISCO
abrir ↗
GitHub PoC★ 5
A simple python script to check if a service is vulnerable
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
GitHub PoC★ 12
imancybersecurity/CVE-2023-27350-POC
CVE-2023-27350CRITICALsob ataqueransomware21 abr 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RISCO
abrir ↗
← anteriorpágina 576 / 2.745próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.